CVE-2026-40375
Analyzed
Analyzed - Analysis Complete
Missing Authorization in Dynamics Business Central Discloses Information
Vulnerability report for CVE-2026-40375, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-11
Last updated on: 2026-08-13
Assigner: Microsoft Corporation
Description
Description
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | dynamics_365_business_central_2025 | From 26.0 (inc) to 26.0.50788 (exc) |
| microsoft | dynamics_365_business_central_2025 | From 27.0 (inc) to 27.0.50789 (exc) |
| microsoft | dynamics_365_business_central_2026 | From 28.0 (inc) to 28.0.50938 (exc) |
| microsoft | dynamics_365_business_central_2024 | From 25.1.25900 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |